MyCERT Advisories

MyCERT Advisories, Alerts and Summaries for the year 2009
Bookmark and Share

MA-149.022009: MyCERT Special Alert - The Microsoft Excel Invalid Object Vulnerability

1.0 Introduction

Microsoft Excel is a spreadsheet application by Microsoft. It features calculation, graphing tools, pivot tables and macro programming language called VBA (Visual Basic for Applications).

2.0 Vulnerability description

The Microsoft Excel invalid object vulnerability is rated as critical because it can allow an attacker to perform remote code execution on an affected system in the eventuality of a successful attack. Attacks against the security flaw generated by a boundary condition error have initially been reported by security company Symantec.

An attacker who successfully exploited this vulnerability could run arbitrary code as the logged-on user. If a user is logged on with administrative user rights, an attacker could take complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

3.0 Software affected

  • Microsoft Office Excel 2000 Service Pack 3
  • Microsoft Office Excel 2002 Service Pack 3
  • Microsoft Office Excel 2003 Service Pack 3
  • Microsoft Office Excel 2007 Service Pack 1
  • Microsoft Office Excel Viewer 2003
  • Microsoft Office Excel Viewer 2003 Service Pack 3
  • Microsoft Office Excel Viewer
  • Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1
  • Microsoft Office 2004 for Mac
  • Microsoft Office 2008 for Mac

4.0 Solutions and workaround

  • Do not open or save Office files that you receive from un-trusted sources or that are received unexpectedly from trusted sources. This vulnerability could be exploited when a user opens a file.

  • Use the Microsoft Office Isolated Conversion Environment (MOICE) when opening files from unknown or un-trusted sources. For more information on MOICE, please refer http://support.microsoft.com/kb/935865

  • Use Microsoft Office File Block policy to block the opening of Office 2003 and earlier documents from unknown or untrusted sources and locations. For more info on Microsoft Office File Block policy , please refer http://support.microsoft.com/kb/922848

Reference